SQL Injection Vulnerability in SourceCodester Medicine Tracker System
CVE-2024-6419
9.8CRITICAL
Summary
A significant SQL injection vulnerability exists within SourceCodester's Medicine Tracker System version 1.0, specifically in the save_medicine function located in the Master.php file. This vulnerability allows attackers to manipulate the 'id' parameter, potentially leading to unauthorized access to the underlying database. The exploit can be executed remotely, posing a serious threat to data integrity and security. With public disclosure of this vulnerability, urgent measures are recommended to mitigate the risks associated with this exploit. Organizations using this system should prioritize patching and apply appropriate security protocols to protect sensitive data.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published